Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dep: cve: bump go-openapi/jsonreference to v0.19.4 #119

Merged
merged 1 commit into from
Jul 20, 2020

Conversation

honza
Copy link
Contributor

@honza honza commented Jul 20, 2020

v0.19.4 bumps x/text to v0.3.3 which in turn mitigates against CVE-2020-14040

https://groups.google.com/g/golang-announce/c/bXVeAmGOqz0?pli=1

cc @casualjim

v0.19.4 bumps x/text to v0.3.3 which in turn mitigates against
CVE-2020-14040

https://groups.google.com/g/golang-announce/c/bXVeAmGOqz0?pli=1

Signed-off-by: Honza Pokorny <honza@redhat.com>
@fredbi fredbi merged commit e7bc266 into go-openapi:master Jul 20, 2020
@honza
Copy link
Contributor Author

honza commented Jul 21, 2020

@fredbi Would you mind tagging the CVE merge commit so we can insist on the new version in our go.mod? Thanks!

@casualjim
Copy link
Member

I've tagged and pushed now

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants